A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope
A dormant contributor account was hijacked to republish every package in the @mastra npm scope with an injected crypto-stealer dependency, illustrating how forgotten accounts with residual publish rights become the weakest link in scope ownership.
Summary written by editorial AI · Source link below
A dormant contributor account was used to republish the entire @mastra npm scope, each injected with a single dependency, easy-day-js, that drops a cross-platform cryptocurrency stealer. Here is how the attack worked, how to check exposure, and how to remediate.
Editorial Analysis
Dormant accounts with residual publishing permissions are a systemic blind spot; enterprise teams must treat contributor lifecycle management as a critical supply-chain control.
Review npm org membership for dormant or former contributor accounts with publish access, and enforce MFA plus periodic access recertification.
An abandoned developer account was exploited to inject malware across an entire npm scope—dormant access rights are a supply-chain liability.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at Snyk Blog in a new tab.
More from the DevSecOps Desk
- CHRONO-RESOLUTION: A Dependency Resolution Dataset at Release Points for npm, PyPI, and crates.io Packages20 Jul
- SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts19 Jul
- Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT17 Jul
- VulnHunter: Capital One's agentic AI code security tool17 Jul
- The Prover Is the Judge: Verified Security Software from AI Coding Agents in Ada/SPARK17 Jul